Privacy policy
Written to be read. Where something costs you privacy, it says so in the same size type as everything else.
Last updated 8 August 2026
The short version
Your mail lives with your mail provider and on your devices. Tiho is the software you read it with. Two of our services touch your mail at all, and both are described below in full: the one that tells you a message arrived, and the one that fetches images so senders can't watch you.
What stays on your device
Messages, attachments, search index, drafts, and the credentials for any mailbox you connect. Credentials are held in the system keychain — the same place your other applications keep passwords — and never in ordinary application settings.
Mail is stored so it can be read without a network. Deleting the account from the app erases the stored mail and the stored credentials from that device.
Notifications, and what they cost
This is the part most policies bury, so it goes first.
To tell you the moment a message arrives, our server keeps a live connection to your mailbox. That requires it to hold access to the mailbox — a token or a password, encrypted at rest.
What it does with that access:
- It observes that something arrived in the folder, and reads that one message’s sender and subject. Nothing else, and neither is stored.
- It encrypts those two lines with a key your device generated and gave to no one else, and sends them as the notification. Your device decrypts them; nothing in between can.
- It does not read, download, or store the body of a message, or anything else in your mailbox.
Delivery runs on the platform’s own channel — Apple’s on iPhone, iPad and Mac, Google’s on Android. There is no other route to a device on either platform. What they carry is the encrypted payload above: both can see that a notification was sent to you, and neither can see who wrote or what about.
What we will not claim: that encryption at rest protects this from us. A service obliged to keep a connection open must be able to read the credentials continuously, so the key sits alongside them. Encryption here protects against a leaked backup or a stolen disk image — a real risk, and a smaller one than the honest description above.
Disconnect the mailbox in the app and the stored access is erased from the server. Turning off notifications has the same effect.
Images in messages
Most messages carry images whose real job is to report that you opened them, and when, and from where. Tiho fetches those images through our own server instead of from your device.
- The sender's server sees a request from us. Not your address, not your IP, not the moment you read.
- We keep nothing about who requested what. The proxy holds no log tying an image to a reader.
- Images of one pixel, and images the sender marked hidden, are never fetched at all — by us or by you. They have no purpose other than reporting on you.
Sender logos
A sender's logo is read from a public record published in their own domain's DNS. The address is the same for every recipient and carries no identifier, so requesting it cannot reveal that you opened a particular message. Logos are cached on your device.
Bulk mail
Campaigns are sent through a delivery service you sign up for yourself, with your own key. We never send on your behalf, and your recipient list never reaches us: it stays on your device, and the addresses go to your delivery service alone, at the moment you press send.
One thing does reach us, and it is the unsubscribe link. Every recipient gets their own, carrying a random value and nothing else — no address, no name, no campaign. When someone follows it, we record that value. Your app asks us about its own values and learns which of them unsubscribed. We cannot work out whose address any of them is, because we were never told.
Why this lives with us at all: a person unsubscribes from their own mail program, and there is no other place to hear about it.
Documents
Used offline, the document editor makes no network connections at all. There is nothing to send and nothing to describe here.
If you subscribe to storage, the documents you choose to sync are stored on our servers so they can reach your other machines. The copy on your disk stays canonical. Cancelling stops the syncing and never strands a file.
What we do not do
- No advertising, and no data sold or shared for it.
- No analytics inside the app that report what you read or who writes to you.
- No third-party requests from this website: fonts, images and scripts are served from here.
Requests from authorities
We answer lawful requests we are obliged to answer, and nothing beyond them. What can be handed over is limited by what exists: for a mailbox we do not host, that is the stored access described above and the fact that a device is registered for notifications — not your correspondence, which we do not hold.
Erasing everything
Disconnecting a mailbox in the app erases the stored mail and credentials from that device, and erases the stored access and the notification registration from our servers. Nothing is kept in reserve.
Changes
If this policy changes in a way that affects what we hold, the change is described here with a date rather than replaced silently.
Contact
Questions about any of this: hello@tiho.one.